CVE-2025-53821
Last modified
CVE-2025-53821 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. An Open Redirect vulnerability exists in the web application prior to version 3.4.5. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. An Open Redirect vulnerability exists in the web application prior to version 3.4.5. The control.php endpoint allows to specify an arbitrary URL via the `nextPage` parameter, leading to an uncontrolled redirection. Version 3.4.5 contains a fix for the issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wegia | Wegia | < 3.4.5 |
References
- https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-f5c2-jmm6-v2c5Exploit, Vendor Advisory
- https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-f5c2-jmm6-v2c5Exploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-53821?
How severe is CVE-2025-53821?
How do I fix CVE-2025-53821?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-538167-Zip is a file archiver with a high compression ratio. Zero…7.5
- CVE-2025-538177-Zip is a file archiver with a high compression ratio. 7-Zi…7.5
- CVE-2025-53818GitHub Kanban MCP Server is a Model Context Protocol (MCP) s…8.9
- CVE-2025-53819Nix is a package manager for Linux and other Unix systems. B…7.9
- CVE-2025-5382Improper access control in users MFA feature in Devolutions …6.8
- CVE-2025-53820WeGIA is an open source web manager with a focus on the Port…6.1
- CVE-2025-53822WeGIA is an open source web manager with a focus on the Port…6.1
- CVE-2025-53823WeGIA is an open source web manager with a focus on the Port…8.8
- CVE-2025-53824WeGIA is an open source web manager with a focus on the Port…5.4
- CVE-2025-53825Dokploy is a free, self-hostable Platform as a Service (PaaS…9.8
- CVE-2025-53826File Browser provides a file managing interface within a spe…9.8
- CVE-2025-53827ownCloud Core is the server-side component of the file stora…9.1
Are you affected by CVE-2025-53821?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
